SQL Injection Vulnerability in DataEase Data Visualization Software
CVE-2026-33084
8.7HIGH
What is CVE-2026-33084?
DataEase, an open-source data visualization platform, contains a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. This flaw occurs because the DatasetDataManage service layer directly incorporates user-supplied sort values into the SQL ORDER BY clause without proper validation. An authenticated attacker can exploit this vulnerability to inject arbitrary SQL commands, potentially leading to time-based blind SQL injection attacks. It is crucial for users of DataEase on versions 2.10.20 and earlier to upgrade to version 2.10.21 or later to mitigate this security risk.
Affected Version(s)
dataease < 2.10.21
